Publish Advisories

GHSA-wvr9-9j3f-xx78
GHSA-3w73-4p4p-f992
GHSA-hvm6-7pfm-582j
GHSA-m7q9-gvvr-wx7v
GHSA-8qhg-c9h2-g6rj
GHSA-vqv8-v28v-329v
GHSA-3c43-5f7q-g3r3
GHSA-c7vr-4qg5-q9v7
GHSA-h9m9-95j2-cpmj
GHSA-q57f-4wj6-3jfc
GHSA-3g55-gxf8-m8xp
GHSA-72mw-x5mh-hqfp
GHSA-236g-v823-mwh3
GHSA-3p7r-f88q-xv28
GHSA-723x-qp2v-v2fc
GHSA-9p45-vf85-gjxg
GHSA-qx3m-6x5p-6m3p
GHSA-r4gp-r2fv-c7gg
GHSA-r74v-xg7r-p9h2
GHSA-2x8c-95vh-gfv4
GHSA-72w8-4vgg-vh67
GHSA-g5qj-pfmg-p3jp
This commit is contained in:
advisory-database[bot]
2024-07-23 21:33:13 +00:00
parent 6419931de2
commit b382951383
22 changed files with 88 additions and 25 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvr9-9j3f-xx78",
"modified": "2022-01-22T00:01:43Z",
"modified": "2024-07-23T21:31:31Z",
"published": "2022-01-16T00:00:44Z",
"aliases": [
"CVE-2020-28919"
],
"details": "A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3w73-4p4p-f992",
"modified": "2022-03-03T00:01:08Z",
"modified": "2024-07-23T21:31:31Z",
"published": "2022-02-23T00:00:59Z",
"aliases": [
"CVE-2022-24564"
],
"details": "Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hvm6-7pfm-582j",
"modified": "2022-03-03T00:00:55Z",
"modified": "2024-07-23T21:31:31Z",
"published": "2022-02-25T00:01:05Z",
"aliases": [
"CVE-2022-24566"
],
"details": "In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7q9-gvvr-wx7v",
"modified": "2022-03-03T00:00:55Z",
"modified": "2024-07-23T21:31:31Z",
"published": "2022-02-25T00:01:05Z",
"aliases": [
"CVE-2022-24565"
],
"details": "Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qhg-c9h2-g6rj",
"modified": "2022-05-13T01:31:06Z",
"modified": "2024-07-23T21:31:31Z",
"published": "2022-05-13T01:31:06Z",
"aliases": [
"CVE-2017-14955"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vqv8-v28v-329v",
"modified": "2022-05-24T17:42:39Z",
"modified": "2024-07-23T21:31:31Z",
"published": "2022-05-24T17:42:39Z",
"aliases": [
"CVE-2020-24908"
],
"details": "Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\\checkmk\\agent\\local directory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3c43-5f7q-g3r3",
"modified": "2023-03-02T18:30:26Z",
"modified": "2024-07-23T21:31:32Z",
"published": "2023-02-20T18:30:16Z",
"aliases": [
"CVE-2022-47909"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-532"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9m9-95j2-cpmj",
"modified": "2023-03-02T18:30:26Z",
"modified": "2024-07-23T21:31:32Z",
"published": "2023-02-20T18:30:16Z",
"aliases": [
"CVE-2022-46836"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q57f-4wj6-3jfc",
"modified": "2023-03-02T21:30:29Z",
"modified": "2024-07-23T21:31:32Z",
"published": "2023-02-20T18:30:16Z",
"aliases": [
"CVE-2022-48321"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-138",
"CWE-79"
],
"severity": "MODERATE",
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-446"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p7r-f88q-xv28",
"modified": "2024-06-06T03:30:57Z",
"modified": "2024-07-23T21:31:35Z",
"published": "2024-06-06T03:30:57Z",
"aliases": [
"CVE-2024-5224"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -96,7 +96,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x8c-95vh-gfv4",
"modified": "2024-07-19T00:31:42Z",
"modified": "2024-07-23T21:31:37Z",
"published": "2024-07-01T15:32:33Z",
"aliases": [
"CVE-2024-6387"
@@ -280,6 +280,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/11/3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/23/4"
}
],
"database_specific": {

Some files were not shown because too many files have changed in this diff Show More